Fake CAPTCHA attacks trick people into running malicious commands under the guise of proving they are human or fixing a browser error. The clearest warning sign is simple: a website’s verification should never ask you to open Run, PowerShell, Terminal, or paste a command. Close the page instead.
What is a fake CAPTCHA or ClickFix attack?
ClickFix is a social-engineering technique: an attacker presents a convincing prompt and persuades the visitor to copy and run attacker-supplied text. Fake CAPTCHA is one possible lure, not the whole technique. The page may show an “I’m not a robot” box or say “Verify You Are Human,” but the dangerous part is the instruction to execute a command.
Microsoft Threat Intelligence and Microsoft Defender Experts describe the usual pattern as a phishing email, malvertisement, or compromised website leading to a visual lure that tricks a person into running a malicious command. Microsoft’s August 21, 2025 analysis explains that the victim’s own action can help the attack evade some automated controls.
Why did reports of fake CAPTCHA attacks grow in late 2024?
Threat researchers reported increasing use of ClickFix during the second half of 2024, but there is no single authoritative worldwide count for that period. The reported timelines reflect different researchers’ observations and telemetry, not a complete census of attacks.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- HHS HC3’s October 29, 2024 alert described earlier ClickFix-style activity in March 2024, fake CAPTCHA infrastructure discovered in August, and phishing lures targeting GitHub users in September. HHS HC3’s sector alert documents those examples.
- Red Canary said paste-and-run activity grew in popularity in the second half of 2024; its own first observation was in August, while other researchers had reported activity as early as March. See Red Canary’s 2024 Threat Detection Report.
- Proofpoint reported an increase in the technique and observed a fake CAPTCHA-themed variant in its email threat data shortly after a relevant open-source toolkit appeared in mid-September. Its November 18, 2024 report described campaigns using the “Verify You Are Human” lure.
A later, specifically bounded indicator comes from ESET: its detection category for ClickFix, HTML/FakeCaptcha, grew by 517% between H2 2024 and H1 2025. ESET said the category represented nearly 8% of all attacks it blocked in that report. Those are ESET telemetry figures for a particular detection classification and period, not totals for all attacks worldwide; ESET also noted that related attack stages may be detected under other names. ESET’s H1 2025 Threat Report gives the figures and their context.
Microsoft separately said that, by the time of its August 2025 analysis, its teams had observed campaigns targeting thousands of enterprise and end-user devices globally every day. That is Microsoft’s observation, not an independently verified global count.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How the fake verification trick works
- You reach a visual lure. It may come from a compromised website, malvertising, a phishing link, a malicious URL, or an HTML attachment. The page can imitate a browser error, a document-opening problem, a familiar online service, reCAPTCHA, or Cloudflare Turnstile.
- The page invents a reason to act. It may claim verification failed, ask you to fix an error, or tell you to complete a “Verify You Are Human” step.
- It directs you to a command environment. The instructions may tell you to open Windows Run, PowerShell, Terminal, or a command prompt and paste text. Some versions put a command on the clipboard without making its contents clear.
- The pasted command starts the next stage. Running it may download or launch scripts and malware. The payload varies; it is not guaranteed that every prompt, click, or command leads to an infection.
Proofpoint reported campaigns delivering malware including AsyncRAT, DanaBot, DarkGate, Lumma Stealer, and NetSupport, among other families. The malware depends on the campaign; a familiar CAPTCHA image does not identify what, if anything, a specific page will deliver. HHS HC3 also documented fake CAPTCHA routes associated with payload delivery in its October 2024 alert.
Red flags to watch for
- A verification page tells you to open Windows Run, PowerShell, Terminal, or a command prompt.
- You are asked to paste clipboard contents that you did not create and cannot inspect.
- A page pairs an ordinary-looking CAPTCHA with unexpected keyboard shortcuts or command-line directions.
- An unexpected link or attachment opens a verification flow, even when the page imitates a familiar service or brand.
The decisive red flag is a web page requesting command execution. A CAPTCHA may ask you to select images or click a checkbox; it should not require you to run a command.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What to do if you see one
- Do not run the command or paste the text. Do not follow keyboard-shortcut instructions from the page.
- Close the tab. If you still need the service, open a new tab and type its known address yourself rather than returning through the suspicious link.
- If you already ran it on a work device, contact IT or security promptly. Report what you clicked, what command or text you entered if known, and when it happened. Follow your organization’s incident-response instructions.
Do not treat a routine antivirus scan as proof that a device is safe after a command has been run. A scan may be one response step, but it does not replace prompt reporting and investigation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How individuals and organizations can reduce risk
For individual users
The most effective immediate safeguard is behavioral: never run a command supplied by a web verification page. Browser warnings and endpoint protection are useful additional layers, not substitutes for that rule. Microsoft describes protections in its own product ecosystem, including SmartScreen warnings, endpoint detection of suspicious process and command-line activity, script scanning, cloud protection, and email protection using fake-CAPTCHA behavioral signatures. Those are vendor-described capabilities, not an independent comparison of products.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
For organizations
- Train users on the specific trick. Explain that verification should not require a command-line action, and show how a fake error or CAPTCHA can be used to persuade a person to run one. Proofpoint specifically recommends user training on ClickFix.
- Inspect links and attachments. Email defenses should account for phishing links and HTML attachments that can lead to a fake verification page.
- Monitor endpoint activity. Look for unusual process chains, command-line activity, and script execution that may follow a user’s interaction with a page.
- Monitor network traffic and correlate signals. HHS HC3 recommends analyzing abnormal traffic and correlating it with process and command-line activity, rather than treating each signal in isolation.
Can a CAPTCHA install malware?
A legitimate CAPTCHA is not the command-running step described here. In a fake CAPTCHA attack, the attacker’s page impersonates verification and persuades the visitor to execute text. The appearance of a checkbox or CAPTCHA branding alone does not establish that malware has been installed; the risk comes from following the page’s instructions to run a command.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

